Request-time evaluation
Evaluate a new package version with vulnerability and policy context before caching and consumption.
Smart Kubaba · Repository Firewall
Match package versions with intelligence and policy to produce PASS, WARN, or BLOCK decisions.

Outcome
Evaluate a new package version with vulnerability and policy context before caching and consumption.
Apply organization, project, or repository policy through one evaluation model.
Manage time-bound risk acceptance with reason, reference, task state, and audit records.
Verified scope
Evaluate package versions requested from proxy repositories against intelligence and applicable policy.
Request ControlReflect policy outcomes in download behavior and the decision record presented to users.
Download DecisionOrganization, project, and repository rules with priority and scope resolution.
Scope ResolutionTime-bound, reasoned, referenced, scoped exceptions with durable tasks and reevaluation.
Risk ExceptionFilterable package/version evaluations, decision history, and audit records.
Decision HistoryFirewall decisions use OSV vulnerability data and severity/policy rules; malware, license, and namespace-confusion analysis are outside this scope.
Current BoundaryRepository Firewall evaluates the requested package version against intelligence and central policy before download.
A user or build tool sends a request to the proxy repository.
Compare package coordinates with available OSV data.
Apply organization, project, and repository policies.
Record the result as PASS, WARN, or BLOCK.
Write downloads, exceptions, and reevaluations to the audit trail.
Enterprise
Central rules resolve by organization, project, and repository scope; roles, access policies, tasks, and audit records show who governs each decision.
Technical evaluation
Let’s review your formats, deployment, and security policies together.